CWE-614: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
The Secure attribute for sensitive cookies in HTTPS sessions is not set.
62 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-53757 — Insecure Cookie Flags Vulnerability in Digisol DG-GR6821AC Router
- CVE-2025-0479 — Security Misconfiguration Vulnerability in CP Plus Router
- CVE-2025-24897 — Misskey CSRF vulnerability due to insecure configuration of authentication cookie attributes
- CVE-2026-53661 — boruta-server sent sensitive session cookies without the Secure attribute
- CVE-2026-46398 — HAX CMS Missing Secure Flag on Cookie
- CVE-2024-58317 — Kentico Xperience <= 13.0.164 Cookie Security Configuration
- CVE-2024-41684 — Cookie Without Secure Flag Set Vulnerability
- CVE-2025-24390 — Missing Cookie Flags
- CVE-2025-52632 — HCL AION is susceptible to Missing Secure Attribute in Encrypted Session (SSL) Cookie vulnerability
- CVE-2025-27450 — CVE-2025-27450
- CVE-2026-57948 — Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
- CVE-2026-32745 — In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
- CVE-2024-47833 — Session Cookie without Secure and HTTPOnly flags in taipy
- CVE-2026-1697 — Use of unsecure cookies for GraphicalData web service and WebClient web app
- CVE-2024-10718 — Cookie without Secure attribute in phpipam/phpipam
- CVE-2026-11956 — TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
- CVE-2026-43828 — Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
- CVE-2026-41017 — Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy
- CVE-2024-28771 — IBM Security Directory Integrator information disclosure
- CVE-2024-28770 — IBM Security Directory Integrator information disclosure
Recently published
- CVE-2026-65655 — Temporal UI Server may set OAuth credential cookies without Secure behind a TLS-terminating reverse proxy
- CVE-2026-15656 — IBM MAS uses axios-1.15.2, protobufjs-8.0.1 and undici-7.26 which is vulnerable to multiple CVEs, and contains vulnerabilities related to missing Secure attribute on mas-redirect-uri cookie and weak HMAC Session Secret
- CVE-2026-48058 — nebula-mesh: Session and OIDC state cookies lack the Secure attribute
- CVE-2026-56581 — HCL MyCloud was affected with Cookie Attribute Path Not Set
- CVE-2024-23572 — HCL Aftermarket EPC is vulnerable to attack as cookie appears to contain a session token, which may increase the risk as
- CVE-2026-57948 — Pinpoint - Insecure Session Cookie Attributes in pinpointJwt
- CVE-2026-46550 — NocoDB: Refresh Token Cookie Set Without `Secure` and `SameSite` Flags
- CVE-2026-53661 — boruta-server sent sensitive session cookies without the Secure attribute
- CVE-2026-11956 — TwiN gatus OIDC Session Cookie oidc.go setSessionCookie missing secure attribute
- CVE-2026-46398 — HAX CMS Missing Secure Flag on Cookie
- CVE-2025-52608 — HCL iControl was affected by Missing Cookie Attributes vulnerability.
- CVE-2026-41017 — Apache Airflow: JWT cookie missing Secure flag in JWTRefreshMiddleware behind HTTPS-terminating proxy
- CVE-2026-43828 — Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set by default
- CVE-2026-22617 — Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacke
- CVE-2026-4820 — IBM Maximo Application Suite was vulnerable to because Cookie ltpatoken2_<workspace_name> was not set with secure flag
- CVE-2026-32745 — In JetBrains Datalore before 2026.1 session hijacking was possible due to missing secure attribute for cookie settings
- CVE-2026-1697 — Use of unsecure cookies for GraphicalData web service and WebClient web app
- CVE-2024-58317 — Kentico Xperience <= 13.0.164 Cookie Security Configuration
- CVE-2025-36249 — IBM Jazz for Service Management is vulnerable to "filter" cookie not sent over SSL
- CVE-2025-52614 — HCL Unica Platform is affected by a Cookie without HTTPOnly Flag Set vulnerability